SY0-701 Security Program Management and Oversight Practice Question
An employee receives an email that says, 'This is the CEO. Buy gift cards now and reply with the codes before the meeting starts.' What should the employee do?
⚠ Common exam trap
The trap here is that candidates may mistake the urgency and authority in the email as legitimate, choosing Option A, but CompTIA tests the principle that any request for sensitive actions (gift cards, wire transfers, credential changes) must be verified through a separate, trusted channel regardless of apparent sender identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the request through an approved channel and report the message
The email exhibits classic social engineering indicators—spoofed authority, urgency, and a request for non-standard financial transactions (gift cards). The employee must verify the request through an approved communication channel (e.g., a phone call to the CEO's known number) and report the message to the security team for incident response. This aligns with security policy for phishing and business email compromise (BEC) prevention, as per NIST SP 800-61 and organizational security awareness training.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reply with the codes because the request appears urgent
Why it's wrong here
Replying with the codes because the request appears urgent plays directly into the social engineer's script: urgency and authority are pressure cues used to bypass rational thought, not proof of identity. Gift card codes are a classic business email compromise (BEC) indicator, and a legitimate CEO would not route a sensitive request solely through email without an approved secondary method. Responding also confirms to the attacker that the address is active, making future targeted attacks more likely. Instead, the recipient should suspend action and verify through an independent, pre-established channel.
- ✓
Verify the request through an approved channel and report the message
Why this is correct
Verifying the request through an approved channel, such as a pre-configured phone number, in-person contact, or the official ticketing system, confirms authenticity without relying on any contact information found in the suspect email itself. Reporting the message to the security or incident response team allows analysts to collect header data, block the sender, and issue warnings to other employees who may have received identical lures. This combination of independent verification and official reporting directly mitigates the current threat and protects the organization from a likely impersonation fraud. Acting alone, either verification or reporting, is insufficient; both together form a complete and secure response.
- ✗
Forward the email to coworkers so they can watch for similar messages
Why it's wrong here
Forwarding the email to coworkers does not verify the requester's identity and instead spreads the malicious payload or fraudulent instructions to additional inboxes, potentially exposing other employees to phishing or malware. It also bypasses the security team's centralized investigation capability, because coworkers may act on the content, forward it again, or delete it before any analysis can occur. The proper approach is to report a single copy to the incident response team and let them conduct a controlled campaign-wide search and warning process. This prevents the email from becoming a secondary distribution vector while still enabling awareness.
- ✗
Delete the email and ignore it without telling anyone
Why it's wrong here
Deleting the email and ignoring it silently destroys digital evidence that cybersecurity analysts need to identify the attacker's source IP, phishing infrastructure, and campaign fingerprints. The threat remains fully active after deletion: the attacker can reuse the same template, target another employee, or continue sending requests from a different spoofed address, and since no report was filed, no defensive controls or alerts will be updated. This also leaves the employee with no record of the attempt, making them more susceptible to a follow-up method that bypasses email. Ignoring a suspected attack never contains it; only reporting enables the organization to detect and block further attempts.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Security awareness
Security awareness is the ongoing practice of educating people within an organization about cybersecurity risks, safe behaviors, and their individual responsibilities to protect information assets.
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.